Back to skill

Security audit

装修设计技巧大全

Security checks for vulnerabilities and agentic risk

Overview

This is a static renovation-advice skill, but parts of its reference material include unsafe gas-inspection and structural-renovation guidance that should be reviewed before use.

Before installing or relying on this skill, review or remove references that advise bypassing gas inspections or casually describe load-bearing wall removal. For gas, structural, electrical, waterproofing, or demolition work, the skill should require local-code compliance and approval from licensed professionals, utilities, property management, and permitting authorities. Apart from those content-safety issues, the package behaves like a static Markdown knowledge base and does not show agentic malware behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
references/ref-144.md:3
Finding
Invisible Unicode Characters Reduce Instruction and Content Auditability## Vulnerability Details **File Location**: `references/ref-144.md:3`, `references/ref-150.md:3`, `references/ref-163.md:3`, and `references/ref-416.md:34-35` **Vulnerability Type**: Unexpected zero-width Unicode characters in agent-consumed Markdown **Risk Level**: Low ### Evidence The affected content contains invisible U+200D ZERO WIDTH JOINER characters. The security-relevant portions are represented below with explicit escapes because the original characters are not visually detectable: ```text references/ref-144.md:3 \u200D[renovation article text begins] references/ref-150.md:3 \u200D[renovation article text begins] references/ref-163.md:3 \u200D\u200D[renovation article text begins] references/ref-416.md:34-35 \u200D \u200D010[renovation article heading continues] ``` ### Technical Analysis The Markdown reference corpus is consumed as contextual material by the AI agent. Invisible Unicode format characters make the effective byte and character sequence differ from what a reviewer sees. This can defeat exact string matching, complicate content-diff review, and provide an obfuscation channel for future instruction injection. No concealed command, executable payload, instruction override, or malicious behavior was identified around the current characters. They appear to be content-import artifacts. The issue is therefore an auditability and content-integrity weakness rather than evidence of an active compromise. ### Attack Path 1. An attacker or compromised content importer introduces agent directives containing or separated by zero-width characters. 2. Visual review presents the altered text as ordinary reference content. 3. Exact-match controls or simple pattern scanners fail to recognize the obfuscated directive. 4. The AI agent consumes the effective text when loading the affected reference. 5. Depending on the added directive and the agent's instruction-handling controls, its response could b ...[truncated 742 chars]
Remediation
## Remediation Suggestions 1. Remove the unexpected U+200D characters from all identified files. 2. Normalize every Markdown file to Unicode NFC during ingestion and before publication. 3. Add a CI check that rejects unexpected characters in the ranges U+200B–U+200D and U+FEFF unless a documented exception exists. 4. Render invisible characters explicitly in code-review diffs, for example as `\u200D`. 5. Re-run instruction-hijacking and encoded-content scans after normalization. 6. Validate imported articles against an allowlist of expected Unicode categories and quarantine files containing unexpected formatting controls.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (622)

Hidden Instructions

High
Category
Prompt Injection
Content
# 一间卧室就有7种布局!感觉自己家又白装了!

卧室功能里头不外乎床、衣柜、斗柜、书桌以及化妆台布局,但是不同布局就有不同的价值,如果盲目去做很有可能功能满足不了,空间价值还得降低。所以今天盘点一下,卧室究竟有多少种更合理的布局,来实现空间价值的最大化。第一、传统布局。传统布局对于小空间来说挤压空间,看似满足了功能,但是空间的价值全无。而且卧室颜色大忌就是灰色,大面积灰色会让空间整体显得廉价。除非空间很大,否则传统的卧室布局,床体居中非常挤压空间,同时也让空间利用率更低。空间很大的话,即使你用传统做法也不会显得空间拥挤,还能满足功能,但是空间小的话,就需要改变布局,满足空间的最大化利用。第二、长条卧室改变传统布局。2米乘以4.5的空间,利用靠最里头打造地台床,实现卧室床铺功能,同时借用了隔壁房间,实现了内嵌的书桌和衣柜功能;让空间更大,也让功能布局更加合理。把床靠窗户布局,长条形的优势发挥出来,衣柜与转角书桌书架一体化布局,同时满足了收纳和办公功能,而且空间利用率更高。长条形一字布局,采用定制榻榻米或者排骨架床,与衣柜以及阳台书桌一字设计,可以满足功能的最大化,同时空间利用率最大化。榻榻米靠窗布局,剩下空间不仅实现了书桌办公,同时收纳量相当于一个小型衣帽间第三、床头靠门放置,提升空间利用率。床头靠门布局,腾出更多空间,利用过道墙面洞洞板收纳,窗下满足学习和办公,提升空间利用率床头靠门,与衣柜双一字布局,过道更宽敞,腾出更多空间价值。调换床头位置,以空间的价值化为主,才是装修的价值都刚需了别讲究风水了,先满足功能要紧,务实价值最大化才是王道第四、小空间,床不要居中放。网友@七十七:自从放弃床铺居中执念后, 我把家里两个卧室的布局都进行了调整, 将床靠墙放置,安全感拉满的同时, 还为房间的其他功能区域腾出更多空间~网友@剌剌:谁懂!11平小房间中间放张1.8米的床真的很拥挤,除了床头柜什么也放不下;不管大床小床都不要居中放,可以试试把床靠窗,这样可以走动的位置就变宽敞了,合理规划好空间,卧室小住起来也可以很舒适网友@葫芦宝:之前我家的床是放在卧室中间,两侧都放不下什么,可以说一张床占据了整个卧室。挪到窗边后空间立刻大了一半,女儿在旁边打个地铺都没有问题。网友@十十:与其床居中 留条窄走道 不如靠墙 放大另一侧空间 但其实是 我不想要两个床头柜网友@佳家:床的面积可以说是卧室里最大的了,所以他的位置摆放几乎可以决定其他家具的位置,秉着最大程度化利用房间的空间,还是将床靠边放,床尾多余的位置可以放上衣架或者衣柜,这样也方便起床后挑选要穿的衣服第五、床头靠窗户。网友@陶二宝:婆婆说:卧室床头不能对着窗户,但是…… 这样布置出来的卧室真的很香!这样的布局不但轻松拥有1.5米大床,还多出来一个学习区域,睡觉学习两不误网友@大莉水手:不理解,为啥床头靠窗摆会挨骂?床头靠窗摆放,放上了好多自己喜欢的物件,换个奶呼呼的吸顶灯,挂上‬喜欢的窗纱,瞬间变得氛围起‬来~ 不像之前又小又窄 - 别对空间做‬约束网友@oblivi:上周突然想把床换个方向试试 没想到卧室大了好多 原本放了伊娃之后床尾空间略有些挤 现在宽敞了很多 甚至可以放下书桌和椅子 并且靠墙后多了份安全感~网友@小J的:父母说床靠窗不吉利,但是真的好舒服啊~突发奇想给床挪到了床边,无床头的床非常适合diy,每天一睡醒就能看到蓝天,心情都会变美丽,但是父母却说床靠窗不吉利。我:小户型还讲究什么吉利不吉利~舒服就行网友@爱格格:卧室太小把床头调整到靠窗,床一侧靠墙空间立马大了很多,看着也不那么挤了,以前怎么没想到这么摆放,现在也不晚吧。网友@冷巴:无头的悬浮床没有空间限制,打破传统的布局,我把床头安排在靠窗位置,空间瞬间大了不少。网友@走堂:小房间可以多改变布局,试试不同的位置或朝向,只要自己舒适,不按常理也好,时时有惊喜和新鲜感。我的床没有床头,也不靠墙,我觉得很好睡,而且房间也因此显大了。第六、床对主卫门,调换床头。网友@美少女:2025年了,还有人要讲究风水,虽然不认同但是很尊重,我不怕厕所对着床,就把床头位置改了,然后得到了一个5米长的床尾衣柜,通风太好了,整个夏天没有开空调,晚上只开了风扇,庆幸自己做了这个选择,而且我还得到了一个超级宽敞的过道网友@彭饱饱:床头原本是靠主卧厕所那边,于是我把床头调转到对面 得到了一个4.5米整面床尾衣柜 整整10扇柜门 可以塞下我和老公两个人的衣服 落地后实用又好看又显空间大,还解决了床头对着厕所的问题 简直是一举多得!网友@小耳朵:三房两卫中间户通病少不了这个卫生间门对床,各位不妨试试换个床头方向,其实也还不错,房间看着也宽敞,也没有卫生间正对床头感觉膈应感。第七、床头不靠墙网友@小兑话:看腻了床头靠墙 一侧窗户一侧卫生间的布局 把床放在了房间
...[truncated 25 chars]
Confidence
85% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# 120㎡通铺大规格木纹砖,没想到效果也这么好

‍‍原木风的主色调为白色➕木色白色作为背景色,占比50%作用于墙面,柜子和门墙面以浅色为主,颜色暖暖的,效果不错!门的颜色可以调色跟柜子颜色做对比,尽量做到颜色统一!木纹砖选择的是平面哑光肌肤釉,普通的拖把就可以拖的很干净客厅双眼皮边吊走一圈,下吊25cm,宽30cm,错层4公分,好看还不压层高客厅的开间是3.5米,把通往阳台的推拉门去掉,拗不过家人包了门套,整体空间看起来宽敞又明亮!600×1200的木纹砖,好多邻居来参观都误以为是木地板 ,大家选择木纹砖一定不要选那种只有一个版面的,版面太少看起来不自然,太多看起来太杂,6到8个比较合适!木纹砖原木风对于刚需房非常友好,能让小空间更温馨,而且可以整体降低造价定制柜主色为暖白色,开放格为木色,房门,踢脚线跟墙面颜色一致,视觉统一和谐没有做复杂的背景墙,简单双眼皮边吊走一圈,乳胶漆墙顶通刷家具选择多以实木成品为主,颜色温润有质感绿色沙发长度2.8米,没有要茶几
5头的棉花吊灯,奶呼呼的很好看,水电阶段没有在床头两边留线所以安了免布线的壁灯!1.8×2米的樱桃实木床+藤编元素床头柜窗帘用的奶油色棉麻布+白色十字纹麻料纱砸掉原本的飘窗改绿植角,放上几盆自己喜欢的花花草草,小房间氛围感满满!樱桃木实木床头简单实用,视觉上不会有压抑感靠窗小书柜满足少量置物,床头壁灯营造氛围感

简单双眼皮走一圈+窗帘盒衣柜没有要一门到顶,做的分段式衣柜+同色拉手地面600✖️1200木纹砖通铺
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# 120㎡通铺大规格木纹砖,没想到效果也这么好

‍‍原木风的主色调为白色➕木色白色作为背景色,占比50%作用于墙面,柜子和门墙面以浅色为主,颜色暖暖的,效果不错!门的颜色可以调色跟柜子颜色做对比,尽量做到颜色统一!木纹砖选择的是平面哑光肌肤釉,普通的拖把就可以拖的很干净客厅双眼皮边吊走一圈,下吊25cm,宽30cm,错层4公分,好看还不压层高客厅的开间是3.5米,把通往阳台的推拉门去掉,拗不过家人包了门套,整体空间看起来宽敞又明亮!600×1200的木纹砖,好多邻居来参观都误以为是木地板 ,大家选择木纹砖一定不要选那种只有一个版面的,版面太少看起来不自然,太多看起来太杂,6到8个比较合适!木纹砖原木风对于刚需房非常友好,能让小空间更温馨,而且可以整体降低造价定制柜主色为暖白色,开放格为木色,房门,踢脚线跟墙面颜色一致,视觉统一和谐没有做复杂的背景墙,简单双眼皮边吊走一圈,乳胶漆墙顶通刷家具选择多以实木成品为主,颜色温润有质感绿色沙发长度2.8米,没有要茶几
5头的棉花吊灯,奶呼呼的很好看,水电阶段没有在床头两边留线所以安了免布线的壁灯!1.8×2米的樱桃实木床+藤编元素床头柜窗帘用的奶油色棉麻布+白色十字纹麻料纱砸掉原本的飘窗改绿植角,放上几盆自己喜欢的花花草草,小房间氛围感满满!樱桃木实木床头简单实用,视觉上不会有压抑感靠窗小书柜满足少量置物,床头壁灯营造氛围感

简单双眼皮走一圈+窗帘盒衣柜没有要一门到顶,做的分段式衣柜+同色拉手地面600✖️1200木纹砖通铺
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# 120㎡通铺大规格木纹砖,没想到效果也这么好

‍‍原木风的主色调为白色➕木色白色作为背景色,占比50%作用于墙面,柜子和门墙面以浅色为主,颜色暖暖的,效果不错!门的颜色可以调色跟柜子颜色做对比,尽量做到颜色统一!木纹砖选择的是平面哑光肌肤釉,普通的拖把就可以拖的很干净客厅双眼皮边吊走一圈,下吊25cm,宽30cm,错层4公分,好看还不压层高客厅的开间是3.5米,把通往阳台的推拉门去掉,拗不过家人包了门套,整体空间看起来宽敞又明亮!600×1200的木纹砖,好多邻居来参观都误以为是木地板 ,大家选择木纹砖一定不要选那种只有一个版面的,版面太少看起来不自然,太多看起来太杂,6到8个比较合适!木纹砖原木风对于刚需房非常友好,能让小空间更温馨,而且可以整体降低造价定制柜主色为暖白色,开放格为木色,房门,踢脚线跟墙面颜色一致,视觉统一和谐没有做复杂的背景墙,简单双眼皮边吊走一圈,乳胶漆墙顶通刷家具选择多以实木成品为主,颜色温润有质感绿色沙发长度2.8米,没有要茶几
5头的棉花吊灯,奶呼呼的很好看,水电阶段没有在床头两边留线所以安了免布线的壁灯!1.8×2米的樱桃实木床+藤编元素床头柜窗帘用的奶油色棉麻布+白色十字纹麻料纱砸掉原本的飘窗改绿植角,放上几盆自己喜欢的花花草草,小房间氛围感满满!樱桃木实木床头简单实用,视觉上不会有压抑感靠窗小书柜满足少量置物,床头壁灯营造氛围感

简单双眼皮走一圈+窗帘盒衣柜没有要一门到顶,做的分段式衣柜+同色拉手地面600✖️1200木纹砖通铺
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# 120㎡通铺大规格木纹砖,没想到效果也这么好

‍‍原木风的主色调为白色➕木色白色作为背景色,占比50%作用于墙面,柜子和门墙面以浅色为主,颜色暖暖的,效果不错!门的颜色可以调色跟柜子颜色做对比,尽量做到颜色统一!木纹砖选择的是平面哑光肌肤釉,普通的拖把就可以拖的很干净客厅双眼皮边吊走一圈,下吊25cm,宽30cm,错层4公分,好看还不压层高客厅的开间是3.5米,把通往阳台的推拉门去掉,拗不过家人包了门套,整体空间看起来宽敞又明亮!600×1200的木纹砖,好多邻居来参观都误以为是木地板 ,大家选择木纹砖一定不要选那种只有一个版面的,版面太少看起来不自然,太多看起来太杂,6到8个比较合适!木纹砖原木风对于刚需房非常友好,能让小空间更温馨,而且可以整体降低造价定制柜主色为暖白色,开放格为木色,房门,踢脚线跟墙面颜色一致,视觉统一和谐没有做复杂的背景墙,简单双眼皮边吊走一圈,乳胶漆墙顶通刷家具选择多以实木成品为主,颜色温润有质感绿色沙发长度2.8米,没有要茶几
5头的棉花吊灯,奶呼呼的很好看,水电阶段没有在床头两边留线所以安了免布线的壁灯!1.8×2米的樱桃实木床+藤编元素床头柜窗帘用的奶油色棉麻布+白色十字纹麻料纱砸掉原本的飘窗改绿植角,放上几盆自己喜欢的花花草草,小房间氛围感满满!樱桃木实木床头简单实用,视觉上不会有压抑感靠窗小书柜满足少量置物,床头壁灯营造氛围感

简单双眼皮走一圈+窗帘盒衣柜没有要一门到顶,做的分段式衣柜+同色拉手地面600✖️1200木纹砖通铺
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# 120㎡通铺大规格木纹砖,没想到效果也这么好

‍‍原木风的主色调为白色➕木色白色作为背景色,占比50%作用于墙面,柜子和门墙面以浅色为主,颜色暖暖的,效果不错!门的颜色可以调色跟柜子颜色做对比,尽量做到颜色统一!木纹砖选择的是平面哑光肌肤釉,普通的拖把就可以拖的很干净客厅双眼皮边吊走一圈,下吊25cm,宽30cm,错层4公分,好看还不压层高客厅的开间是3.5米,把通往阳台的推拉门去掉,拗不过家人包了门套,整体空间看起来宽敞又明亮!600×1200的木纹砖,好多邻居来参观都误以为是木地板 ,大家选择木纹砖一定不要选那种只有一个版面的,版面太少看起来不自然,太多看起来太杂,6到8个比较合适!木纹砖原木风对于刚需房非常友好,能让小空间更温馨,而且可以整体降低造价定制柜主色为暖白色,开放格为木色,房门,踢脚线跟墙面颜色一致,视觉统一和谐没有做复杂的背景墙,简单双眼皮边吊走一圈,乳胶漆墙顶通刷家具选择多以实木成品为主,颜色温润有质感绿色沙发长度2.8米,没有要茶几
5头的棉花吊灯,奶呼呼的很好看,水电阶段没有在床头两边留线所以安了免布线的壁灯!1.8×2米的樱桃实木床+藤编元素床头柜窗帘用的奶油色棉麻布+白色十字纹麻料纱砸掉原本的飘窗改绿植角,放上几盆自己喜欢的花花草草,小房间氛围感满满!樱桃木实木床头简单实用,视觉上不会有压抑感靠窗小书柜满足少量置物,床头壁灯营造氛围感

简单双眼皮走一圈+窗帘盒衣柜没有要一门到顶,做的分段式衣柜+同色拉手地面600✖️1200木纹砖通铺
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Natural-Language Policy Violations

High
Confidence
97% confidence
Finding
This markdown content includes natural-language advice to evade safety and compliance controls: building a temporary fake wall to pass gas-company inspection and then removing it afterward. That is a clear policy and safety violation because it encourages circumvention of building/gas safety requirements rather than lawful, safe remediation.

Missing User Warnings

High
Confidence
97% confidence
Finding
The text explicitly discusses removing walls and even references demolishing a load-bearing wall with reinforcement, yet it gives no caution about severe structural risk, permits, or the necessity of licensed engineering review. This omission is safety-critical because the described actions could endanger people and property if followed casually.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The instruction '不去 AI 味,用西安装修课堂"过日子"的口吻' requires responses to use a specific linguistic style tied to a particular locale/voice. This is a natural-language policy concern because it imposes a language/locale presentation preference without indicating that the user can choose another language or style.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The usage section again instructs the skill to '用西安装修课堂"过日子"的口吻,说人话、给干货', which hard-codes a localized communication style. Because no opt-in or alternative language/style path is provided, this can violate language/locale policy expectations.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
SQP-3 applies to all file types and covers language or locale policy violations. This file presents all user-facing guidance only in Chinese and does not indicate that the skill is region-specific, optional by locale, or that users can choose another language.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The entire file is written in Chinese and provides no indication that the user can choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which it is not here.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The entire file is written in Chinese and is specifically framed around the Xi'an market, with no indication that users may choose another language or locale. Under the policy rule for natural-language violations, forcing a specific language/locale without opt-in is reportable unless the regional constraint is explicitly documented and justified as a region-specific tool.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
SQP-3 applies to all file types and covers language or locale policy violations. This markdown content presents all instructions and user-facing text exclusively in Chinese, with no indication that users can choose another language or that the content is intentionally limited to a Chinese-speaking audience.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The entire skill file is written exclusively in Chinese and is explicitly localized to Xi'an/Shaanxi, including region-specific recommendations such as '西安地区'. There is no indication that users may choose another language or locale, nor a clear statement that the skill is intentionally limited to a China/Xi'an-specific audience for compliance or other justified reasons.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The entire skill content is written exclusively in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the stated policy, language constraints require opt-in or clear justification to avoid a locale policy violation.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file presents all user-facing content in a single language, Chinese, with no indication that the user can choose another language or that the skill is intended only for a Chinese-speaking audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
This markdown file presents the skill content only in Chinese and does not indicate that the user can choose another language or that the content is intended solely for a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
This markdown content imposes a specific language on the user, which matches the policy category for language or locale constraints without user opt-in. There is no indication that the skill is region-specific or that users may choose another language.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
This markdown file presents all instructions and guidance exclusively in Chinese and does not offer any language or locale choice. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The entire skill file is written in Chinese and provides content only in that language, with no indication that the user can choose another language or locale. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file presents all user-facing content in a single forced language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified, which is not present here.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The entire skill content is presented only in Chinese, with no indication that language selection is optional or limited to a justified region-specific context. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The file’s natural-language content is fully presented in Chinese and does not offer any opt-in, alternative language, or explanation that the skill is intended only for Chinese-speaking users. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The entire skill file is written exclusively in Chinese and provides no indication that language selection is optional or user-configurable. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified, which is not present here.

Static analysis

No suspicious patterns detected.